AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-3252

HIGH · CVSS 7.5 EPSS 2.59%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-02-23 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-3252
Severity
HIGH
CVSS
7.5
EPSS
2.59%
Java

Original NVD Description

KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in plain-text from the local server during the KACO XP100U authentication process, regardless of whatever passwords have been provided, which leads to an information disclosure vulnerability.